Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

Encryption Battle Reignited as US Govt at Loggerheads With Apple

Apple and the US government are at loggerheads for the second time in four years over unlocking iPhones connected to a mass shooting, reviving debate over law enforcement access to encrypted devices.

Apple and the US government are at loggerheads for the second time in four years over unlocking iPhones connected to a mass shooting, reviving debate over law enforcement access to encrypted devices.

Attorney General Bill Barr claimed Monday that Apple failed to provide “substantive assistance” in unlocking two iPhones in the investigation into the December shooting deaths of three US sailors at a Florida naval station, which he called an “act of terrorism.”

Apple disputed Barr’s claim, while arguing against the idea of “backdoors” for law enforcement to access its encrypted smartphones.

“We reject the characterization that Apple has not provided substantive assistance in the Pensacola investigation,” the company said in a statement.

“Our responses to their many requests since the attack have been timely, thorough and are ongoing.”

The standoff highlighted the debate between law enforcement and the tech sector about encryption — a key way to protect the privacy of digital communications, but which can also make investigations difficult, even with a court order.

The latest battle is similar to the dispute between Apple and the US Justice Department after the December 2015 mass shooting in San Bernardino, California, when the iPhone maker rejected a request to develop software to break into the shooter’s iPhone.

That fight ended in 2016 when the government paid an outside party a reported $1 million for a tool that circumvented Apple’s iPhone encryption.

Advertisement. Scroll to continue reading.

Barr last year called on Facebook to allow authorities to circumvent encryption to fight extremism, child pornography and other crimes. The social network has said it would move ahead with strong encryption for its messaging applications.

– Opening wrong doors?

Digital rights activists argue that any privileged access for law enforcement would weaken security and make it easier for hackers and authoritarian governments to intercept messages.

“We have always maintained there is no such thing as a backdoor just for the good guys,” Apple’s statement said.

“Backdoors can also be exploited by those who threaten our national security and the data security of our customers.”

Apple and others argue that digital “breadcrumbs” make it increasingly easy to track people, even without breaking into personal devices.

The government’s latest demand “is dangerous and unconstitutional, and would weaken the security of millions of iPhones,” Jennifer Granick of the American Civil Liberties Union said in a statement.

“Strong encryption enables religious minorities facing genocide, like the Uighurs in China, and journalists investigating powerful drug cartels in Mexico, to communicate safely.”

Granick added that Apple cannot allow the FBI access to encrypted communications “without also providing it to authoritarian foreign governments and weakening our defenses against criminals and hackers.”

Kurt Opsahl of the Electronic Frontier Foundation echoed that sentiment, saying Apple “is right to provide strong security” for its devices.

“The AG (attorney general) requesting Apple re-engineer its phones to break that security is a poor security trade-off, and imperils millions of innocent people around the globe,” Opsahl tweeted.

James Lewis of the Center for Strategic and International Studies, a Washington think tank, said he believes it’s possible to allow law enforcement access without sacrificing encryption.

“You’re not weakening encryption, you’re making it so it’s not end-to-end,” Lewis told AFP.

“It means that there’s a third party who can look at it under appropriate authority.”

But Lewis said he does not expect either side to come out a winner in the battle, and that US officials will likely find another outside party to crack the two iPhones belonging to the shooter, Royal Saudi Air Force 2nd Lieutenant Mohammed Saeed Alshamran, who died in the attack.

“It’s a repeat of the movie we saw in San Bernardino,” he said.

“It’s going to be harder because Apple probably fixed the trick that worked in San Bernardino.”

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

Shaun Khalfan has joined payments giant PayPal as SVP, CISO.

More People On The Move

Expert Insights

Related Content

Malware & Threats

Apple’s cat-and-mouse struggles with zero-day exploits on its flagship iOS platform is showing no signs of slowing down.

Mobile & Wireless

Samsung smartphone users warned about CVE-2023-21492, an ASLR bypass vulnerability exploited in the wild, likely by a spyware vendor.

Mobile & Wireless

Infonetics Research has shared excerpts from its Mobile Device Security Client Software market size and forecasts report, which tracks enterprise and consumer security client...

Fraud & Identity Theft

A team of researchers has demonstrated a new attack method that affects iPhone owners who use Apple Pay and Visa payment cards. The vulnerabilities...

Mobile & Wireless

Critical security flaws expose Samsung’s Exynos modems to “Internet-to-baseband remote code execution” attacks with no user interaction. Project Zero says an attacker only needs...

Mobile & Wireless

Apple rolled out iOS 16.3 and macOS Ventura 13.2 to cover serious security vulnerabilities.

Mobile & Wireless

Two vulnerabilities in Samsung’s Galaxy Store that could be exploited to install applications or execute JavaScript code by launching a web page.

Mobile & Wireless

Asus patched nine WiFi router security defects, including a highly critical 2018 vulnerability that exposes users to code execution attacks.